Peter Bassill — latest writing on cyber security
Latest articles · page 10 of 13
-
Continuous learning at scale
Post 11 of the AI series. EmilyAI has been learning from analyst feedback for six years. The LLM-as-frozen-artefact shape gets the operational properties of *the model that improves over time* structurally wrong. What that means in practice.
-
Installing GoPhish on Ubuntu 24.04 LTS and Configuring DNS for Phishing Simulation
Deploy GoPhish with Postfix on Ubuntu, configure SPF, DKIM, DMARC, CAA and SRV records for your sending domains, and import campaign templates.
-
Computer Use and the operator question
Post 10 of the AI series. Anthropic's Computer Use, OpenAI's Operator, Google's Project Astra. The category where AI literally moves the mouse. What this shape changes for cyber operations — and how it reads against EmilyAI's tighter action vocabulary.
-
Year in cyber AI 2024: what was real, what was not
Post 9 of the AI series. The 2024 retrospective. Six security copilots shipped; one major outage reshaped the resilience conversation; reasoning models arrived; agents mostly did not. The honest read going into 2025.
-
The law, the insurance, the incident plan, and the culture that holds it all together
Year-end consolidation. Your UK GDPR obligations, cyber insurance, the one-page incident response plan you need, and how to build a security culture that lasts beyond this series.
-
Agentic AI, year one: the demo vs the deployment
Post 8 of the AI series. AI agents in cyber operations have been demoed everywhere this year. The agent that actually ships looks different from the demo. The honest read after twelve months — and the shape of agent EmilyAI already is, not by accident.
-
Passing it on: to the next director, to your children
Part 18 of 18, the closing post. The privacy work you have done over the last two years has to outlive you in the role. How to write it down, how to teach it, and how to make sure the people who inherit it can actually use it.
-
AI-powered threats — and the usage policy you actually need
AI is making phishing better and deepfake fraud cheaper. It is also a real risk when your own staff paste customer data into ChatGPT. Both sides of the AI coin, and a simple policy that handles both.
-
Building a personal privacy posture
Part 17 of 18. Sixteen posts of specifics, condensed into a posture rather than a list. The five sentences that should govern personal privacy for a board director and their household. How to keep it current.
-
The basics you can pick up and walk away with: physical security and social media
Screen locks, premises, disposing of old kit, USB drives, social media account security, and the risks of oversharing. The unglamorous but high-leverage controls that prevent entire categories of attack.
-
Reasoning models: what o1 changes for SOC work
Post 7 of the AI series. OpenAI's o1 launched in September with a different model shape — *think longer, reason step by step*. What this means for the SOC, where the gains are real, and where EmilyAI's purpose-specific architecture continues to win.
-
The AI year, deepfakes, and what changes for children
Part 16 of 18, last of the five children-focused posts. Generative AI changed what 'a picture of a child' can mean. What parents should be alert to in 2024, what is genuinely new, and the practical conversations that still work.
-
Backups: the only thing that recovers you from ransomware
The 3-2-1 rule, what to back up, why testing your backups is more important than having them, and the specific changes that protect backups from modern ransomware.
-
Single-vendor concentration: the CrowdStrike lesson applied to AI
Post 6 of the AI series. The July 2024 CrowdStrike outage was not an AI incident, but it tells us a great deal about where the AI-in-security market is heading. Why single-vendor concentration of intelligent agents is a structural risk worth modelling now.
-
CrowdStrike: cyber resilience without a bad actor
Four weeks after the CrowdStrike Falcon update that took 8.5 million Windows machines offline, the post-mortem is in. The interesting question is not what CrowdStrike did wrong. It is what the rest of us did wrong by assuming this kind of event could not happen.